Cyber Resilience Act
Physical connection
Legal definition Art. 3(9) CRA
“a connection between electronic information systems or components implemented using physical means, including through electrical, optical or mechanical interfaces, wires or radio waves”
The physical connection is one of three connection terms the Cyber Resilience Act (CRA) defines for itself. Under Article 3(9) it is a connection between electronic information systems or components implemented using physical means. The examples given are electrical, optical or mechanical interfaces, wires and radio waves.
Radio waves count as a physical connection
The most consequential part of the definition sits at the end of that list. Wi-Fi, Bluetooth, NFC, cellular, Zigbee and LoRaWAN are physical connections in the sense of the CRA, with no cable anywhere in sight.
The line against the Logical connection therefore does not run between cable and radio but between the transmission medium and the software. A connection is logical under Article 3(8) when it is a virtual representation of a data connection implemented through a software interface. On a connected device both forms are normally present at once: the radio link as the physical connection, the network socket riding on it as the logical one. Nothing requires you to choose, because a single variant suffices.
The list is not exhaustive
The Regulation introduces its examples with the word “including”. Electrical, optical and mechanical interfaces, wires and radio waves are illustrations of physical means, not a closed list. What falls under it includes:
- electrical: Ethernet, USB, serial ports, fieldbuses, contact pads and connectors
- optical: fibre, infrared and optical couplers
- mechanical: card slots, docking connectors and module sockets
Whether an interface is standardised, brought out to the housing or documented at all makes no difference to the definition.
What the connection runs between
Article 3(9) names its two ends differently from Article 2(1). Article 2(1) speaks of a data connection to a device or network; the definition speaks of a connection between electronic information systems or components. An electronic information system is, under Article 3(7), a system including electrical or electronic equipment capable of processing, storing or transmitting digital data. A component is, under Article 3(6), software or hardware intended for integration into such a system.
The definition also does not require data to flow across the connection. That word appears only in Article 2(1), which asks for a physical data connection. A line carrying nothing but power satisfies the notion of a physical connection, yet it does not establish scope. How the whole test is built is set out under Data connection.
What the term does for scope
Article 2(1) requires the intended purpose or reasonably foreseeable use to include a direct or indirect, logical or physical data connection to a device or network. The physical connection is one of four combinations, and one of them is enough.
Recital 9 describes what the obligation attaches to: both products that can be connected physically via hardware interfaces and products that are connected logically. What governs is the wording of Article 2(1), and that turns on intended purpose and reasonably foreseeable use, not on operating state. A device that never reaches a network at the customer site does not drop out of scope for that reason alone.
What hangs on physical interfaces in substance
The term does not only open the scope, it reaches into the requirements. Annex I, Part I, point 2 applies on the basis of the cybersecurity risk assessment under Article 13(2) and only where applicable. Point 2(j) then requires products to be designed, developed and produced to limit attack surfaces, including external interfaces. Point 2(d) requires protection from unauthorised access by appropriate control mechanisms, at least authentication, identity or access management systems, and reporting on possible unauthorised access.
Article 13(3) requires the risk assessment to rest on intended purpose and reasonably foreseeable use, expressly including the operational environment. Every interface physically present therefore belongs in that assessment, whether or not it is used in operation.
When the interface is the product
Annex III, class I, point 10 lists physical and virtual network interfaces as a product category of their own. A product with the core functionality of that category is, under Article 7(1), an important product with digital elements. Article 32(2) then governs class I. Where the manufacturer has not applied harmonised standards, common specifications or a European cybersecurity certification scheme at assurance level at least “substantial”, has applied them only in part, or none exist, the product must go through EU type-examination under module B followed by module C, or full quality assurance under module H. Anyone placing network cards, bus interface boards or radio modules on the market as products in their own right should settle this early. What else belongs to this group is set out on the pages for important and critical products.
Article 7(1) also makes clear that integrating such a product does not in itself render the product it is integrated into subject to the procedures in Article 32(2) and (3). Anyone building in a finished radio module therefore need not put their own product through those procedures on that ground alone.
Practical questions
-
The definition draws no line between internal and external interfaces; a populated UART or JTAG header is a physical connection. Whether it carries scope is decided by Article 2(1) through reasonably foreseeable use. On a device opened for repair or commissioning, use of that header is close at hand; for test pads reachable only with a factory fixture, the opposite case is easier to make. Either way the header belongs in the risk assessment under Article 13(3), and anyone treating a requirement as inapplicable must give a clear justification in the Technical documentation under Article 13(4).
-
No. Recital 30 records that the CRA essential cybersecurity requirements include all the elements of the essential requirements in Article 3(3), points (d), (e) and (f), of Directive 2014/53/EU. Annex I reaches beyond them, and the CRA conformity assessment is a procedure of its own. The same recital names Delegated Regulation (EU) 2022/30, which makes those requirements applicable to certain radio equipment, and anticipates that the Commission will repeal or amend it so that it ceases to apply to certain products covered by the CRA. For the transitional period that recital says the Commission should provide guidance to manufacturers subject both to the CRA and to that Delegated Regulation, to facilitate demonstrating compliance with the two Regulations.
-
On the wording yes, because Article 3(9) expressly names connections between components, and an SPI or I2C bus is an electrical interface. That alone does not establish scope: Article 2(1) asks for a data connection to a device or network, not to a part inside the same housing. In practice the route runs through the indirect connection in Article 3(10), once the assembly forms part of a larger system that is itself connectable. Internal buses stay relevant for the requirements regardless, because the risk assessment under Article 13(3) covers the operational environment.
This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.